Back to Glossary

Anonymisation

Anonymisation is stripping data of anything that could identify a person, and done properly it takes the data outside UK GDPR entirely.

Anonymisation is the process of altering data so that individuals can no longer be identified from it. Done properly, the result is no longer personal data, which means UK GDPR stops applying to it.

That is a significant thing to achieve, and it is why anonymisation is usually the cheapest route through a data project that would otherwise be blocked.

The bar is higher than removing names

The common assumption is that deleting the name column does it. It does not.

The test is whether an individual can be identified by any means reasonably likely to be used, including by combining the data with other information that is available. A dataset with names removed but containing postcode, date of birth and job title may still identify someone, particularly in a small population.

Think about it from the position of someone trying: what else would they need, and could they plausibly get it?

Anonymisation is not pseudonymisation

This distinction is frequently blurred and matters a great deal.

Pseudonymisation replaces identifying details with a code, while you keep the key that reverses it. It is a security safeguard, it is explicitly encouraged, and the data remains personal data. All the obligations still apply.

Anonymisation is irreversible. Nobody, including you, can get back to the individual. Only this takes the data out of scope.

If you have kept a lookup table, you have pseudonymised.

Where it helps most

Most commercial value in a data project sits in patterns rather than individuals. "Jobs of this type run 19 per cent over on average" needs no personal data at all.

So the practical move is to strip identifiers at the start rather than at the end. A project designed around aggregate output usually has a much easier path, both legally and technically, than one that processes identifiable records and anonymises the results.

What it does not solve

Anonymisation addresses data protection. It does not address confidentiality.

For professional services firms in particular, engagement letters and professional rules often restrict the use of client information more tightly than the law does, and those obligations do not have an automatic carve-out for aggregate insight. Check the contracts as well as the regulation, because the contracts are usually quicker to check and can stop a project earlier.

Have a Question About Anonymisation?

We're happy to explain how this applies to your specific business. No jargon, no pressure.